CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3102

As cited

Copy frozen at (site build).

vulnerabilities

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

A Russian state-backed espionage group exploited a previously unknown vulnerability in Zimbra's webmail client to access email messages, directories, saved passwords, and two-factor authentication recovery codes over a period of months. The malicious payload extracted the last 90 days of emails and required only message opening to execute. U.S. government agencies including NSA (National Security Agency) and CISA (Cybersecurity and Infrastructure Security Agency) subsequently issued guidance on the matter.

Why it matters: Organizations using Zimbra webmail face compromise of email communications and 2FA bypass mechanisms; practitioners should patch immediately and review access logs for suspicious activity.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary